D62000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000001.00000000.1210633095.0000000000D62000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D62000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Njrat |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
Yara signature match |
System Summary |
|
|
64CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670820437.00000000064CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64CA000
|
Size: |
4096
|
|
994000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241624348.0000000000994000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
994000
|
Size: |
8192
|
|
1760000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669571278.0000000001760000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1760000
|
Size: |
4096
|
|
5460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670206985.0000000005460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5460000
|
Size: |
65536
|
|
1677000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669344049.0000000001677000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1677000
|
Size: |
4096
|
|
43D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.00000000043D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43D1000
|
Size: |
163840
|
|
990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239578499.0000000000990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
990000
|
Size: |
126976
|
|
460B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.000000000460B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
460B000
|
Size: |
139264
|
|
4F61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242087028.0000000004F61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F61000
|
Size: |
12288
|
|
1160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668478433.0000000001160000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1160000
|
Size: |
4096
|
|
1680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669389721.0000000001680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1680000
|
Size: |
4096
|
|
9F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241021873.00000000009F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F2000
|
Size: |
53248
|
|
4512000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.0000000004512000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4512000
|
Size: |
139264
|
|
1140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245223718.0000000001140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1140000
|
Size: |
4096
|
|
9C95000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009C95000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9C95000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
132E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245244134.000000000132E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
132E000
|
Size: |
8192
|
|
4F7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242270279.0000000004F7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F7B000
|
Size: |
8192
|
|
9FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242193107.00000000009FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9FA000
|
Size: |
20480
|
|
990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240120761.0000000000990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
990000
|
Size: |
4096
|
|
D60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1210606583.0000000000D60000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D60000
|
Size: |
4096
|
|
9D75000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009D75000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D75000
|
Size: |
253952
|
|
996000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239959772.0000000000996000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
996000
|
Size: |
28672
|
|
33D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669721389.00000000033D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33D1000
|
Size: |
49152
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243308684.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
4096
|
|
57EB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670353357.00000000057EB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57EB000
|
Size: |
20480
|
|
C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245117358.0000000000C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C40000
|
Size: |
4096
|
|
9A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241675972.00000000009A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A5000
|
Size: |
40960
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239746579.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
73728
|
|
9A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241664100.00000000009A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A2000
|
Size: |
53248
|
|
168C000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669447091.000000000168C000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
168C000
|
Size: |
4096
|
|
4F67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245402733.0000000004F67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F67000
|
Size: |
8192
|
|
4F61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241072772.0000000004F61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F61000
|
Size: |
4096
|
|
959000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242980571.0000000000959000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
959000
|
Size: |
81920
|
|
12A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.00000000012A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A9000
|
Size: |
16384
|
|
5F0D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670535055.0000000005F0D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F0D000
|
Size: |
12288
|
|
974000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239510219.0000000000974000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
974000
|
Size: |
4096
|
|
990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239510219.0000000000990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
990000
|
Size: |
126976
|
|
4F73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240803436.0000000004F73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F73000
|
Size: |
40960
|
|
53E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670156568.00000000053E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53E0000
|
Size: |
4096
|
|
4F7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241979671.0000000004F7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F7A000
|
Size: |
12288
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242018558.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
1870000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669633784.0000000001870000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1870000
|
Size: |
24576
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242130237.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
7E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244038234.00000000007E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E5000
|
Size: |
16384
|
|
60D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670658759.00000000060D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
188416
|
|
4F6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240819024.0000000004F6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F6E000
|
Size: |
20480
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240768919.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
61440
|
|
556E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670255959.000000000556E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
556E000
|
Size: |
8192
|
|
96D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240120761.000000000096D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96D000
|
Size: |
16384
|
|
937000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243042786.0000000000937000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
937000
|
Size: |
69632
|
|
9A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243063354.00000000009A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A6000
|
Size: |
167936
|
|
6550000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670906528.0000000006550000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6550000
|
Size: |
4096
|
|
99D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.00000000099D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
99D1000
|
Size: |
1556480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4F69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241979671.0000000004F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F69000
|
Size: |
45056
|
|
94D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244494717.000000000094D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94D000
|
Size: |
36864
|
|
87BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671164968.00000000087BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
87BA000
|
Size: |
16384
|
|
4F69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240865640.0000000004F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F69000
|
Size: |
20480
|
|
99F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241215775.000000000099F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99F000
|
Size: |
65536
|
|
4F7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245420500.0000000004F7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F7C000
|
Size: |
4096
|
|
60CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670641676.00000000060CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60CD000
|
Size: |
12288
|
|
991000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240049514.0000000000991000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
991000
|
Size: |
20480
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243963224.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
8192
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240968611.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
12288
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239510219.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
143360
|
|
9D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240768919.00000000009D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D1000
|
Size: |
8192
|
|
9FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241044603.00000000009FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9FC000
|
Size: |
12288
|
|
1136000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668428042.0000000001136000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1136000
|
Size: |
40960
|
|
9A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242424145.00000000009A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A2000
|
Size: |
184320
|
|
1697000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669492770.0000000001697000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1697000
|
Size: |
4096
|
|
5FCD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670597412.0000000005FCD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FCD000
|
Size: |
12288
|
|
48B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245282975.00000000048B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
48B0000
|
Size: |
40960
|
|
58EC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670398618.00000000058EC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58EC000
|
Size: |
16384
|
|
1325000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668956155.0000000001325000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1325000
|
Size: |
12288
|
|
5CCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670423001.0000000005CCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CCE000
|
Size: |
8192
|
|
974000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240120761.0000000000974000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
974000
|
Size: |
4096
|
|
167A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669366127.000000000167A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
167A000
|
Size: |
4096
|
|
174C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669553375.000000000174C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
174C000
|
Size: |
16384
|
|
956000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242360814.0000000000956000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
956000
|
Size: |
94208
|
|
4F67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242087028.0000000004F67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F67000
|
Size: |
8192
|
|
12D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243515116.00000000012D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D0000
|
Size: |
4096
|
|
9CEB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009CEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9CEB000
|
Size: |
278528
|
|
9A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239828630.00000000009A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A5000
|
Size: |
40960
|
|
5F4D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670553878.0000000005F4D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F4D000
|
Size: |
12288
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242018558.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
69632
|
|
9AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243218011.00000000009AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AC000
|
Size: |
143360
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240466538.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
24576
|
|
900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244204467.0000000000900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
900000
|
Size: |
36864
|
|
12FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.00000000012FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12FE000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669649912.0000000001890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1890000
|
Size: |
65536
|
|
5400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670191482.0000000005400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5400000
|
Size: |
4096
|
|
96E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241550922.000000000096E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96E000
|
Size: |
151552
|
|
7B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243946022.00000000007B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
4096
|
|
996000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241232610.0000000000996000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
996000
|
Size: |
8192
|
|
6570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670925753.0000000006570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6570000
|
Size: |
4096
|
|
166C000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669322773.000000000166C000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
166C000
|
Size: |
4096
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244696994.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
4096
|
|
96D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240272170.000000000096D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96D000
|
Size: |
176128
|
|
1682000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669411124.0000000001682000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1682000
|
Size: |
4096
|
|
96D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240833344.000000000096D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96D000
|
Size: |
270336
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245138548.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
16384
|
|
96E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242397853.000000000096E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96E000
|
Size: |
163840
|
|
449E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.000000000449E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
449E000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4F64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242006150.0000000004F64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F64000
|
Size: |
20480
|
|
9A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242489101.00000000009A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A5000
|
Size: |
172032
|
|
998000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240255834.0000000000998000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
998000
|
Size: |
98304
|
|
1692000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669478270.0000000001692000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1692000
|
Size: |
4096
|
|
4DEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245306122.0000000004DEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DEF000
|
Size: |
4096
|
|
920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244204467.0000000000920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
920000
|
Size: |
94208
|
|
18A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669670370.00000000018A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18A0000
|
Size: |
40960
|
|
444B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.000000000444B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
444B000
|
Size: |
135168
|
|
1652000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669165325.0000000001652000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1652000
|
Size: |
8192
|
|
1170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668507429.0000000001170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1170000
|
Size: |
8192
|
|
96F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240522806.000000000096F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96F000
|
Size: |
147456
|
|
878E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671164968.000000000878E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
878E000
|
Size: |
4096
|
|
99E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240548762.000000000099E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99E000
|
Size: |
73728
|
|
1540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669103195.0000000001540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1540000
|
Size: |
16384
|
|
4F67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241004432.0000000004F67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F67000
|
Size: |
8192
|
|
1220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.0000000001220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
24576
|
|
4F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245367695.0000000004F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F40000
|
Size: |
135168
|
|
9AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243308684.00000000009AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AF000
|
Size: |
131072
|
|
9D31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009D31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D31000
|
Size: |
12288
|
|
6573000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670925753.0000000006573000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6573000
|
Size: |
176128
|
|
12A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.00000000012A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A1000
|
Size: |
28672
|
|
994000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241550922.0000000000994000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
994000
|
Size: |
8192
|
|
9AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240623692.00000000009AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AC000
|
Size: |
16384
|
|
99E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240583868.000000000099E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99E000
|
Size: |
73728
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240193301.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
12288
|
|
957000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240193301.0000000000957000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
957000
|
Size: |
364544
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245138548.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
36864
|
|
93A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244204467.000000000093A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
93A000
|
Size: |
57344
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244696994.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241174658.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
57344
|
|
74E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243613579.000000000074E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74E000
|
Size: |
8192
|
|
4F62000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240910061.0000000004F62000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F62000
|
Size: |
28672
|
|
9FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242961017.00000000009FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9FD000
|
Size: |
8192
|
|
465E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.000000000465E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
465E000
|
Size: |
139264
|
|
956000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241120018.0000000000956000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
956000
|
Size: |
94208
|
|
9D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240741096.00000000009D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D1000
|
Size: |
188416
|
|
136E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245263477.000000000136E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
136E000
|
Size: |
8192
|
|
996000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242349139.0000000000996000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
996000
|
Size: |
24576
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668956155.0000000001320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
16384
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242424145.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
4096
|
|
9D35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009D35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D35000
|
Size: |
36864
|
|
55FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670274402.00000000055FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55FC000
|
Size: |
16384
|
|
620E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670718456.000000000620E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
620E000
|
Size: |
8192
|
|
9F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241033900.00000000009F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F7000
|
Size: |
32768
|
|
165A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669200772.000000000165A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
165A000
|
Size: |
8192
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243308684.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
103A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668316493.000000000103A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
103A000
|
Size: |
24576
|
|
1690000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669464089.0000000001690000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1690000
|
Size: |
4096
|
|
96E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242360814.000000000096E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96E000
|
Size: |
163840
|
|
994000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244588916.0000000000994000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
994000
|
Size: |
8192
|
|
1662000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669269164.0000000001662000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1662000
|
Size: |
24576
|
|
C3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245087644.0000000000C3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C3F000
|
Size: |
4096
|
|
75B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243613579.000000000075B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
4096
|
|
630E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670764360.000000000630E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
630E000
|
Size: |
8192
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242424145.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242880084.0000000000970000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
970000
|
Size: |
155648
|
|
53F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670174599.00000000053F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53F0000
|
Size: |
4096
|
|
974000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239578499.0000000000974000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
974000
|
Size: |
4096
|
|
644E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670805523.000000000644E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
644E000
|
Size: |
8192
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239566585.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
24576
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243063354.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
95C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244563299.000000000095C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
95C000
|
Size: |
69632
|
|
5E0C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670484460.0000000005E0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E0C000
|
Size: |
16384
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244696994.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
4096
|
|
4705000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.0000000004705000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4705000
|
Size: |
135168
|
|
12B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.00000000012B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12B4000
|
Size: |
290816
|
|
8FE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244155143.00000000008FE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
8192
|
|
4F71000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240865640.0000000004F71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F71000
|
Size: |
8192
|
|
10B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245197583.00000000010B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
4096
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243218011.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
9A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244658806.00000000009A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A7000
|
Size: |
32768
|
|
999000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241232610.0000000000999000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
999000
|
Size: |
12288
|
|
9D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242489101.00000000009D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D2000
|
Size: |
16384
|
|
4F7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240865640.0000000004F7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F7A000
|
Size: |
12288
|
|
9AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240369592.00000000009AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AC000
|
Size: |
16384
|
|
65B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243596473.000000000065B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65B000
|
Size: |
20480
|
|
75E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243613579.000000000075E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75E000
|
Size: |
8192
|
|
166A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669296721.000000000166A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
166A000
|
Size: |
4096
|
|
12AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.00000000012AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12AE000
|
Size: |
20480
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243063354.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
4096
|
|
AFF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244969674.0000000000AFF000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AFF000
|
Size: |
4096
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240409641.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
12288
|
|
9A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244638444.00000000009A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A0000
|
Size: |
20480
|
|
753000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1243613579.0000000000753000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
753000
|
Size: |
20480
|
|
1530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669032857.0000000001530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1530000
|
Size: |
8192
|
|
56E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670311216.00000000056E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56E0000
|
Size: |
4096
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242130237.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
69632
|
|
46B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.00000000046B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
46B2000
|
Size: |
135168
|
|
94D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239940114.000000000094D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94D000
|
Size: |
4096
|
|
1228000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.0000000001228000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1228000
|
Size: |
16384
|
|
9FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242282781.00000000009FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9FD000
|
Size: |
8192
|
|
9F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242282781.00000000009F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F3000
|
Size: |
12288
|
|
9A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240605333.00000000009A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A5000
|
Size: |
45056
|
|
67AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671037051.00000000067AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67AD000
|
Size: |
12288
|
|
65A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670925753.00000000065A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
65A0000
|
Size: |
258048
|
|
6450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670820437.0000000006450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6450000
|
Size: |
380928
|
|
974000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240070053.0000000000974000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
974000
|
Size: |
4096
|
|
993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240484111.0000000000993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
993000
|
Size: |
118784
|
|
5F8B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670577829.0000000005F8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F8B000
|
Size: |
20480
|
|
94B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241198063.000000000094B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94B000
|
Size: |
45056
|
|
9F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242207331.00000000009F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F6000
|
Size: |
16384
|
|
4565000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.0000000004565000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4565000
|
Size: |
139264
|
|
168A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669432420.000000000168A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
168A000
|
Size: |
4096
|
|
94E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242018558.000000000094E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
528384
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240502767.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
77824
|
|
9F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242257089.00000000009F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F2000
|
Size: |
16384
|
|
9AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239877991.00000000009AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AC000
|
Size: |
12288
|
|
998000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240925227.0000000000998000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
998000
|
Size: |
94208
|
|
9B4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009B4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9B4E000
|
Size: |
1335296
|
|
16DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669522188.00000000016DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16DE000
|
Size: |
8192
|
|
7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244038234.00000000007E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
16384
|
|
96D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242227483.000000000096D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96D000
|
Size: |
192512
|
|
99C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242130237.000000000099C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99C000
|
Size: |
208896
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242114619.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
24576
|
|
94B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239705337.000000000094B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
94B000
|
Size: |
12288
|
|
186E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669617313.000000000186E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
186E000
|
Size: |
8192
|
|
996000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240548762.0000000000996000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
996000
|
Size: |
28672
|
|
993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240952468.0000000000993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
993000
|
Size: |
20480
|
|
634E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670788253.000000000634E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
634E000
|
Size: |
8192
|
|
122E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668565142.000000000122E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
122E000
|
Size: |
413696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
5DCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670466698.0000000005DCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DCF000
|
Size: |
4096
|
|
4EEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245337225.0000000004EEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4EEF000
|
Size: |
4096
|
|
95B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240070053.000000000095B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
95B000
|
Size: |
90112
|
|
90A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244204467.000000000090A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
90A000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
99D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241159002.000000000099D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99D000
|
Size: |
73728
|
|
1210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3668533438.0000000001210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
20480
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240968611.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
61440
|
|
959000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240409641.0000000000959000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
959000
|
Size: |
356352
|
|
9EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242282781.00000000009EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EF000
|
Size: |
12288
|
|
9F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242282781.00000000009F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F8000
|
Size: |
8192
|
|
B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1245061894.0000000000B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B3E000
|
Size: |
8192
|
|
1660000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669236711.0000000001660000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1660000
|
Size: |
8192
|
|
68AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671082906.00000000068AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
68AE000
|
Size: |
8192
|
|
990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240070053.0000000000990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
990000
|
Size: |
4096
|
|
33DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669721389.00000000033DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33DE000
|
Size: |
307200
|
|
16E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669538007.00000000016E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16E0000
|
Size: |
4096
|
|
6A2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671102450.0000000006A2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6A2D000
|
Size: |
12288
|
|
9DB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009DB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9DB4000
|
Size: |
2011136
|
|
4F67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241072772.0000000004F67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F67000
|
Size: |
8192
|
|
45B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669779362.00000000045B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
45B8000
|
Size: |
139264
|
|
99F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240030973.000000000099F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99F000
|
Size: |
24576
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1242489101.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
4096
|
|
95A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239578499.000000000095A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
95A000
|
Size: |
94208
|
|
9FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244943289.00000000009FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9FE000
|
Size: |
4096
|
|
99A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1244615589.000000000099A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99A000
|
Size: |
8192
|
|
18E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3669704294.00000000018E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18E0000
|
Size: |
20480
|
|
991000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240300823.0000000000991000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
991000
|
Size: |
28672
|
|
9D3F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671267987.0000000009D3F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D3F000
|
Size: |
217088
|
|
6B2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3671146214.0000000006B2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B2E000
|
Size: |
8192
|
|
99F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1239959772.000000000099F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99F000
|
Size: |
24576
|
|
9AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241696798.00000000009AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AC000
|
Size: |
12288
|
|
9EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1243218011.00000000009EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9EE000
|
Size: |
4096
|
|
563C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3670291637.000000000563C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
563C000
|
Size: |
16384
|
|
96E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240314580.000000000096E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96E000
|
Size: |
143360
|
|
169B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669507270.000000000169B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
169B000
|
Size: |
4096
|
|
99F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240336985.000000000099F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99F000
|
Size: |
69632
|
|
9AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240706918.00000000009AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9AF000
|
Size: |
327680
|
|
9A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240356002.00000000009A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A5000
|
Size: |
45056
|
|
18C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3669687937.00000000018C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18C0000
|
Size: |
12288
|
|
99C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1241056429.000000000099C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
99C000
|
Size: |
77824
|
|
948000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1240243701.0000000000948000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
948000
|
Size: |
24576
|
|